831
|
5.4 |
MEDIUM
Network
|
themehat
|
super_addons_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themehat Super Addons for Elementor allows DOM-Based XSS.This issue affects Super Addons f…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-51588
|
2024-11-15 05:26 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
832
|
5.4 |
MEDIUM
Network
|
softfirm
|
definitive_addons_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Softfirm Definitive Addons for Elementor allows Stored XSS.This issue affects Definitive A…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-51587
|
2024-11-15 05:26 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
833
|
5.4 |
MEDIUM
Network
|
bu
|
bu_slideshow
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boston University (IS&T) BU Slideshow allows Stored XSS.This issue affects BU Slideshow: f…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-52351
|
2024-11-15 05:24 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
834
|
5.4 |
MEDIUM
Network
|
crm2go
|
crm2go
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CRM 2go allows DOM-Based XSS.This issue affects CRM 2go: from n/a through 1.0.
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-52350
|
2024-11-15 05:22 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
835
|
6.8 |
MEDIUM
Physics
|
-
|
-
|
Windows USB Video Class System Driver Elevation of Privilege Vulnerability
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2024-43637
|
2024-11-15 05:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
836
|
8.1 |
HIGH
Network
|
-
|
-
|
LightGBM Remote Code Execution Vulnerability
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2024-43598
|
2024-11-15 05:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
837
|
8.1 |
HIGH
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating controlle…
Update
|
CWE-352
Origin Validation Error
|
CVE-2024-51484
|
2024-11-15 05:14 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
838
|
5.4 |
MEDIUM
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users delete messages. This vulner…
Update
|
CWE-352
Origin Validation Error
|
CVE-2024-51488
|
2024-11-15 05:12 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
839
|
8.1 |
HIGH
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating plugins. …
Update
|
CWE-352
Origin Validation Error
|
CVE-2024-51485
|
2024-11-15 05:06 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
840
|
8.4 |
HIGH
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. The vulnerability exists in the interface section of the Ampache menu, where users can change the "Custom URL?-?Favicon". Th…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-51486
|
2024-11-15 04:55 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|